Protect What Matters Most — Proactively.

GHS helps organizations across Saudi Arabia achieve and sustain regulatory compliance through rigorous GRC programs — NCA ECC, SAMA CSF, ISO 27001, PDPL, and Aramco CCC/CCC+ — backed by realistic attack simulation and practical, actionable remediation guidance.

8+
Compliance Frameworks
100+
Clients Protected
300+
Assessments Done

Our Experience with Leading Compliance and Cybersecurity Frameworks

NCA ECC SAMA CSF ISO 27001 PCI DSS NIST CSF GDPR CIS Controls SOC 2 Aramco CCC (SACS-210) Aramco CCC+ (SACS-210)
GHS security operations team at work
15+
Combined years of offensive & defensive security expertise

About Us

Your Trusted Cybersecurity Partner in Saudi Arabia

Gray Hat Security (GHS) is a specialist cybersecurity consultancy dedicated to helping organizations understand and reduce real-world risk. Rather than checkbox compliance, we simulate genuine adversary behavior and translate findings into practical, prioritized action — so leadership can make confident, informed decisions.

Our Mission

Empower organizations across the Kingdom to defend their digital landscape with clarity, rigor, and speed.

Our Vision

To be the region's most trusted name in proactive, adversary-informed cybersecurity consulting.

8+ Compliance Frameworks
100+ Clients Protected
300+ Assessments Done

Our Services

GRC-Led Cybersecurity Solutions

Governance, risk, and compliance sit at the center of what we do — reinforced by offensive testing that validates the controls your compliance program depends on.

Most Requested

Governance, Risk & Compliance

We help you build — or mature — a governance program aligned to the frameworks that matter in the Kingdom,…

Learn More

Aramco CCC & CCC+ (SACS-210)

Supplying or contracting with Saudi Aramco means meeting its Third-Party Cybersecurity Standard (SACS-210). We help vendors prepare for and achieve…

Learn More

Penetration Testing

We combine manual, adversary-style techniques with proven tooling to test your external and internal networks, web and mobile applications, APIs,…

Learn More

Vulnerability Assessment

We combine industry-leading scanning tools with manual validation to eliminate false positives, then rank every finding by real business impact…

Learn More

Active Directory Security Testing

Active Directory is the backbone of most enterprise networks — and the top target for attackers. We map real privilege-escalation…

Learn More

Baseline Testing

Before you can improve your security posture, you need to know where you stand. We benchmark your core controls —…

Learn More
SACS-210 · SAUDI ARAMCO

Aramco CCC & CCC+ Certification Packages

Fixed-scope Aramco CCC and CCC+ certification support for suppliers across Saudi Arabia. Three ways to get certified, depending on whether your own IT team implements the technical controls, GHS runs the whole programme for you, or you're a small business with under 5 employees. Every package covers the full TPC1.1–1.33 control set and both SACS-210 certification levels.

New to SACS-210? Read our complete Aramco CCC certification guide or, if you are a critical vendor, the CCC+ requirements breakdown.

Package 1

With IT Support

You have an internal IT team. We provide the full documentation set and guide them through implementation.

From SAR 8,999 SAR 7,649.15

Your IT team implements, we guide

SAVE 15%
  • Full TPC1.1–1.33 documentation set — policies, registers and checklists
  • Gap assessment against your current environment
  • Scheduled advisory calls through implementation
  • Your IT team deploys technical controls with our guidance
  • Audit firm liaison and pre-audit readiness review
Request a Quote

Package 3

Small Business

For companies with fewer than 5 employees. A right-sized documentation set and support scoped to your headcount.

From SAR 7,705.88 SAR 6,550

For teams under 5 employees

SAVE 15%
  • Full TPC1.1–1.33 documentation set, scoped to a small-team environment
  • One scoping and classification call
  • Self-implementation guide
  • Audit firm liaison
Request a Quote

Every package covers CCC — base-tier Aramco certification

Aramco CCC Certification: Common Questions

What is the difference between Aramco CCC and CCC+?

CCC is the base-tier Cybersecurity Compliance Certificate required of Saudi Aramco suppliers under SACS-210. CCC+ applies to vendors classified as critical — those with deeper access to Aramco systems or data — and adds an on-site audit alongside the document review. Your contract classification determines which one you need.

How long does Aramco CCC certification take?

With IT Support and a team ready to implement, a few weeks is realistic. Without IT Support typically runs longer because GHS deploys all technical controls for you, and CCC+ adds time for audit preparation. The single biggest variable is how much policy and evidence already exists before we start.

How much does Aramco CCC certification cost?

Our Saudi National Day offer takes 15% off all packages until 30 September 2026: SAR 7,649.15 for the With IT Support package, where your internal IT team implements the technical controls with our guidance (normally SAR 8,999); SAR 9,349.15 for the Without IT Support package, where GHS runs the entire two-year programme for you (normally SAR 10,999); and SAR 6,550 for the Small Business package, scoped for companies with fewer than 5 employees (normally SAR 7,705.88). Fees for the Aramco-appointed certification body are separate and paid directly by you, as are any software or hardware you choose to buy.

Do we need CCC to keep working with Saudi Aramco?

Yes. SACS-210 makes cybersecurity certification a contractual requirement for suppliers, and Aramco verifies status during onboarding and renewal. Suppliers who let certification lapse risk losing eligibility for new work.

What is SACS-210?

SACS-210 is Saudi Aramco's Third Party Cybersecurity Standard — the unified standard that replaced SACS-002. It defines the controls a supplier must implement and evidence in order to earn CCC or CCC+ certification.

Do you support certification renewal?

Yes. Certification is not one-and-done — it requires ongoing surveillance and periodic renewal. Our Without IT Support package includes two years of continuous evidence and renewal management, plus support through re-audit if needed.

Implementation services only. All packages cover advisory, documentation, remediation guidance and audit support. Software licences, hardware, and Aramco's own certification body fees are not included and are billed directly to you by the respective vendor.

Why Choose GHS

Advanced Security Solutions for a Digital-First Kingdom

We go beyond automated scans. Our certified consultants think like real attackers, so your organization is prepared for threats that matter — not just checkboxes.

Deep Regulatory Expertise

Hands-on experience across NCA ECC, SAMA CSF, ISO 27001, PDPL, and Aramco CCC/CCC+ — we speak the language of Saudi regulators fluently.

Certified, Local Experts

A Riyadh-based team of certified GRC and security professionals who understand the local regulatory landscape.

Realistic Attack Simulation

We test the way real adversaries operate, giving your compliance program evidence — not just a checklist.

Actionable, Prioritized Reporting

Every engagement ends with a clear, audit-ready roadmap — not a 200-page PDF nobody reads.

300+
Assessments Completed
95%
Client Retention Rate
8+
Compliance Frameworks
6
Core Service Areas

Our Process

How We Work With You

01

Discovery & Scoping

We align on objectives, systems in scope, and compliance requirements.

02

Testing & Assessment

Our team simulates real-world attacks and evaluates controls in depth.

03

Reporting

Findings are prioritized by business impact with clear executive summaries.

04

Remediation Support

We help your team fix issues and verify closure with retesting.

"

Testimonials

Hear From Our Satisfied Clients

★★★★★

"Preparing for our NCA ECC audit felt overwhelming until GHS stepped in. They turned a maze of requirements into a practical roadmap our whole team could actually follow."

★★★★★

"GHS's ability to tailor their engagement to our exact environment was impressive. Their in-depth knowledge and reporting expertise helped us identify and resolve issues before they became real problems."

★★★★★

"GHS found critical vulnerabilities in our e-commerce platform that two previous vendors had missed entirely. Their report was clear enough that our developers had everything patched within a single sprint."

★★★★★

"Our move to the cloud came with risks we didn't fully understand. GHS's cloud security review caught misconfigurations that could have exposed customer data, before they became a real problem."

★★★★★

"The Active Directory assessment was eye-opening — GHS mapped an entire privilege escalation path we had no idea existed. Their hardening recommendations were implemented within weeks."

Insights & Research

From the GHS Blog

View All Articles

Get In Touch

Ready to Discuss Your Cybersecurity Needs?

Reach out directly and one of our consultants will get back to you to scope a free initial assessment.

Headquarters
97 King Fahad Branch Rd, Al Olaya Dist., Riyadh, KSA 12611
WhatsApp
+966 5 9898 6267
Email
info@ghs.sa

Discover How We Can Support Your Security Advancement.

Contact Us Today